Compliance Library Blog Product Sign In

GDPR

General Data Protection Regulation (EU) 2016/679

EU Version 1.0 630 obligations
Showing 276–300 of 630 obligations

Title I — General Data Protection Regulation (GDPR)

Chapter I — General Provisions

Chapter II — Principles

Chapter III — Rights of the Data Subject

Chapter IV — Controller and Processor

Article 43. Certification bodies

11 obligations

GDPR-43-02 Requirement

Member States must ensure certification body accreditation

Member States must ensure that certification bodies are accredited by either the competent supervisory authority or the

GDPR-43-03 Conformity

Demonstrate independence and expertise for accreditation

Certification bodies must demonstrate their independence and expertise in relation to the subject-matter of the certific

GDPR-43-04 Conformity

Respect approved certification criteria

Certification bodies must undertake to respect the criteria referred to in Article 42(5) and approved by the supervisory

GDPR-43-05 Documentation

Establish certification management procedures

Certification bodies must establish procedures for the issuing, periodic review and withdrawal of data protection certif

GDPR-43-06 Transparency

Establish transparent complaint handling procedures

Certification bodies must establish procedures and structures to handle complaints about infringements of the certificat

GDPR-43-07 Conformity

Demonstrate absence of conflicts of interest

Certification bodies must demonstrate to the satisfaction of the competent supervisory authority that their tasks and du

GDPR-43-08 Conformity

Ensure proper assessment for certification decisions

Certification bodies are responsible for the proper assessment leading to the certification or the withdrawal of such ce

GDPR-43-09 Reporting

Provide reasons for certification decisions to supervisory authorities

Certification bodies must provide the competent supervisory authorities with the reasons for granting or withdrawing the

GDPR-43-10 Transparency

Publish requirements and criteria publicly

Supervisory authorities must make the requirements referred to in paragraph 3 and the criteria referred to in Article 42

GDPR-43-11 Reporting

Transmit requirements and criteria to the Board

Supervisory authorities must transmit the requirements and criteria to the Board.

GDPR-43-12 Monitoring

Revoke accreditation when conditions not met

The competent supervisory authority or national accreditation body must revoke an accreditation of a certification body

Chapter V — Transfers of Personal Data to Third Countries or International Organisations

Article 44. General principle for transfers

2 obligations

Article 45. Transfers on the basis of an adequacy decision

11 obligations

GDPR-45-01 Requirement

Commission must assess adequacy considering specific elements

The Commission must take account of rule of law, human rights, legislation, data protection rules, case-law, data subjec

GDPR-45-02 Requirement

Commission must decide on adequacy through implementing acts

The Commission may decide, by means of implementing act, that a third country, territory, specified sectors, or internat

GDPR-45-03 Requirement

Commission must provide periodic review mechanism in implementing acts

The implementing act must provide for a mechanism for periodic review, at least every four years, taking into account al

GDPR-45-04 Requirement

Commission must specify territorial and sectoral application in implementing acts

The implementing act must specify its territorial and sectoral application and, where applicable, identify the superviso

GDPR-45-05 Requirement

Commission must adopt implementing acts under examination procedure

The implementing act must be adopted in accordance with the examination procedure referred to in the regulation.

GDPR-45-06 Monitoring

Commission must monitor developments in third countries on ongoing basis

The Commission must continuously monitor developments in third countries and international organisations that could affe

GDPR-45-07 Requirement

Commission must repeal, amend or suspend inadequate adequacy decisions

The Commission must repeal, amend or suspend adequacy decisions when information reveals that adequate protection is no

GDPR-45-08 Requirement

Commission must adopt suspension acts under examination procedure

Implementing acts that repeal, amend or suspend adequacy decisions must be adopted in accordance with the examination pr

GDPR-45-09 Requirement

Commission must adopt immediately applicable acts on urgent grounds

On duly justified imperative grounds of urgency, the Commission must adopt immediately applicable implementing acts in a

GDPR-45-10 Requirement

Commission must consult with third countries to remedy inadequacy situations

The Commission must enter into consultations with the third country or international organisation with a view to remedyi

GDPR-45-11 Transparency

Commission must publish adequacy status list in Official Journal and website

The Commission must publish in the Official Journal of the European Union and on its website a list of third countries,

Article 46. Transfers subject to appropriate safeguards

1 obligation

Start your compliance assessment

Map obligations to your AI systems, identify gaps, and generate board-ready reports. Plans start at $149/mo.

Get Started